Where security signals surface
Every thread carries a live sentiment score, and for security that’s a useful early-warning layer: a user who’s been phished or locked out reads as frustrated fast, and Magic Sentiment scores that from the conversation and rolls it up to a company average. Watch the low-scoring threads — they’re often the ones where something is actually wrong. Sentiment is also an escalation trigger. You can configure a low score to fire an automatic escalation and post a recap using a template your team defines, so a souring security thread routes to the right board or person without a human noticing it first.Sentiment analysis starts only after the customer has sent at least three messages, and the very first message is excluded — early frustration is normal in IT support. Treat the score as a trend signal on a live conversation, not a verdict on the first line.
Investigate with Super Magic — read is always safe
Super Magic is your investigator in the ticket. It reads freely (tickets, contacts, clients, and knowledge), and looking things up never changes anything, so you can dig without touching state. Open it while viewing a thread and it already has that ticket’s context.Act only with confirmation
When investigation turns into response, Super Magic switches modes, and this is the safety property to put in front of whoever reviews security at your company:- Every write action shows a Confirm action card first. Before anything changes, you see the exact action, a plain-language description, and every detail (which ticket, which status, which contact). Nothing runs until you click Confirm.
- Actions record under the individual member, never a faceless service account. When a responder confirms an escalation or note, the ticket history shows that person did it. Accountability holds end to end.
- Access is layered and admin-controlled. Write access is set to All members, Admins only, or a custom list, with a per-tool toggle on every action. Intents and Flows are always admin-only.
Take device action from the ticket — with NinjaOne
When a security thread needs a machine touched (reboot a compromised endpoint, restart a service, flip maintenance mode, reset an alert) NinjaOne connected to Super Magic lets you do it from the chat instead of pivoting to the RMM. Two properties make this safe to allow:- Device actions are writes, so they’re always behind a Confirm action card. Look-ups (device health, active alerts, recent activity, Windows services) are read-only; reboots, service restarts, maintenance mode, alert resets, and device approvals all confirm first.
- Each member acts under their own NinjaOne permissions. NinjaOne connects in two layers, an admin configures the workspace connection once, and every technician signs in with their own NinjaOne account. Super Magic can never do more on a device than that member could do signed into NinjaOne directly, so your existing NinjaOne role assignments keep enforcing.
NinjaOne for Super Magic is a limited release. Contact your Thread account team to enable it, then follow the two-layer setup on Connect NinjaOne to Super Magic.
Next
That’s how security work moves through the desk. Next: the data-handling and permissions story you’ll defend to clients and auditors.How Thread handles your data
Encryption, Magic AI privacy, sub-processors, IP allowlisting, and app permissions.